| 1 | /** |
| 2 | * Whether a request came from another site: its `Origin` names an origin |
| 3 | * other than the site's own. Form posts from g1t's pages carry the site's |
| 4 | * origin; a request without the header (not from a browser's form) is not |
| 5 | * cross-site. lib/session.server.ts's `assertSameOrigin` refuses these on |
| 6 | * every action, for a session cookie and an access token alike |
| 7 | * (lib/website-token.ts). |
| 8 | */ |
| 9 | export function crossOrigin(request: Request): boolean { |
| 10 | const origin = request.headers.get("origin"); |
| 11 | return Boolean(origin && origin !== new URL(request.url).origin); |
| 12 | } |